Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
Remediation
References
Related Vulnerabilities
WordPress Plugin World Travel Information Cross-Site Scripting (1.0.0)
Drupal Core 7.x Multiple Security Bypass Vulnerabilities (7.0 - 7.25)
Apache Tomcat Other Vulnerability (CVE-2008-0002)
WordPress Plugin YouTube Embed Cross-Site Scripting (5.0.1)
phpMyFAQ Misinterpretation of Input Vulnerability (CVE-2023-0880)